CSIDB logo
Incident

Kering

Incident posture

Attack window
2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:46

Linked entities

Victim
Kering
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Kering Group, the French luxury goods conglomerate, suffered a cyberattack in which an unauthorized third party temporarily gained access to its internal systems, affecting fashion brands including Gucci, Balenciaga, and Alexander McQueen. The incident exposed the personal information of millions of customers globally, creating potential risks of identity theft and fraud. The breach highlighted vulnerabilities within the retail and luxury goods sector, as the stolen data could be exploited for further malicious activity. This incident was recognized as one of the most significant cyber events of the year due to its scale, the high-profile nature of the affected brands, and its broader implications for data security in the luxury retail industry.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In April 2025, an unauthorized third party temporarily gained access to the internal systems of Kering Group, the French multinational luxury goods conglomerate that owns fashion brands such as Gucci, Balenciaga, and Alexander McQueen. The intrusion exposed the personal information of millions of customers worldwide, placing Kering among the most significant cyber incidents of the year as later documented by Tokio Marine HCC International. The breach highlighted how attackers could penetrate the internal infrastructure of a major luxury retailer and reach sensitive customer data maintained across the group's well-known fashion houses. The incident drew attention because of both the global footprint of the affected brands and the scale of the customer base whose personal details were potentially compromised.

The cyberattack disrupted operations and data integrity within Kering's internal environment, affecting brands that operate internationally and serve large customer populations. Once inside the network, the unauthorized party was able to reach and extract personal customer information, the nature of which was significant enough to affect millions of individuals globally. The intrusion is recorded among the top cyber incidents of 2025 in a report compiled by Tokio Marine HCC International's Cyber Security team, which selected cases for their operational disruption, financial impact, and broader implications for the global digital ecosystem. The inclusion of the Kering incident alongside major events such as the Marks & Spencer ransomware attack, the Jaguar Land Rover ransomware attack, and large-scale cloud outages reflects the magnitude of disruption the breach caused across the retail and luxury goods sectors. While specific technical details about the initial access vector, the duration of the unauthorized presence, or the exact categories of data exposed are not described in the available reporting, the incident is characterized by the temporary nature of the access and the wide-ranging exposure of personal information belonging to customers of multiple Kering-owned brands. The fact that the breach was identified as a top incident by the insurance and cyber underwriting community indicates that the financial and reputational consequences were considered material, even though precise loss figures or customer notification metrics were not disclosed in the cited reporting. The Kering Group incident, alongside other major events of 2025, underscored the continuing risk that sophisticated threat actors pose to consumer-facing organizations and the systemic exposure that arises when internal systems holding large volumes of personal data are compromised.

Sources

Sources available to members: 1 source.

CSIDB